Tamil₿TC -தமிழ்பிடீசி
861 subscribers
13.2K photos
124 videos
125 files
11.3K links
Download Telegram
Only Banking Ban
Thanks
Anubis Virus Major Announcement (Pay Attention and Spread This if You Are Following This Channel)

If you are an Android user, you need to scan your device to ensure that you have not been compromised by a potent virus called the 'Anubis' virus.

This virus has the ability to render 2FA void via a MITM (man-in-the-middle) attack.

In addition, this virus could even render certain encryptions (i.e., DSAs like ECDSA) via a timing attack.

This virus is extremely sophisticated and it is targeting blockchain users specifically.

Make sure that you read this report. This was put out with particular urgency because it does not appear that this has been covered in the blockchain sphere at all for some reason. There are numerous cybersecurity experts in other sectors of this tech space that have written about this virus (including ZDnet as recently as this month).

Below is the link to the first report:

https://blog.zerononcense.com/2019/07/27/anubis-virus-major-android-virus-attacking-bitfinex-binance-exchange-apps-and-others-pt-1/
Targeted Blockchain Applications

To be specific, the term, ‘targets’ (in reference to the below listed financial & blockchain applications) does not mean that the entities listed are being attacked directly. The entity that has been compromised in this situation is the infected user device.

However, the virus does not become active until the user decides to visit one of these sites (edit: it more than likely is also collecting information from infected users before they visit any of the targeted sites). The virus is programmed to execute its script remotely to begin extracting details from users as soon as they visit these sites by using one of the many methods that was listed in the previous message. Thus, the virus is ‘targeting’ certain sites as the platforms that they wish to infiltrate via compromising the platform’s users first.

Targeted Blockchain Applications:

Binance (com{.}binance{.}dev); Edit: Removed hyperlink

Binance: Cryptocurrency & Bitcoin Exchange (com.binance.odapplications)

Zebpay India (com.bitcoin.ss.zebpayindia)

Bitfinex (com.bitfinex.bfxapp)

Aplikacja Bitmarket (com.bitmarket.trader)

Blockfolio — Bitcoin and Cryptocurrency Tracker (com.blockfolio.blockfolio)

BtcTurk Bitcoin Borsasi (com.btcturk)

Coin Profit (com.coin.profit)

Coinbase — Buy Bitcoin & more. Secure Wallet. (com . coinbase . android)

LocalBitCoins (com.coins.bit.local)

LocalBitCoins NEW (com.coins.ful.bit)

Crypto App — Widgest, Alerts, News, Bitcoin Prices (com.crypter.cryptocurrency)

Bitcoin Blockchain Explorer (com.jackpf.blockchainsearch)

Local Bitcoin (com.jamalabbasii1998.localbitcoin)

Jaxx Blockchain Wallet (com.kryptokit.jaxx)

LocalBitcoins — Buy and sell Bitcoin (com{.}localbitcoins{.}exchange)

LocalBitCoins Official (com.localbitcoinsmbapp)

Coin Market-Bitcoin Prices, Currencies, BTC, EUR, ICO

Mycelium Bitcoin Wallet (com.mycelium.wallet)

Poloniex (com.plunien.poloniex)

Coinbase Tracker (3rd party) {com.portfolio.coinbase_tracker}

LocalBitCoins (com.thunkable.android.manirana54.LocalBitCoins)

UNBLOCK Local BitCoins (com.thunkable.android.manirana54.LocalBitCoins_unblock)

UNOCOIN LIVE (com.thunkable.android.snatoshmehta364.UNOCOIN_LIVE)

Coin Portfolio for Bitcoin & Altcoin tracker (com.tnx.apps.coinportfolio)

Unocoin Wallet (com.unocoin.unocoinwallet)

Blockchain Merchant (info.blockchain.merchant)

Delta — Bitcoin & Cryptocurrency Portfoolio Tracker (io . getdelta . android)

Blockchain Wallet. Bitcoin, Bitcoin Cash, Ethereum (piuk . blockchain . android)

QIWI Wallet (ru . mw)

Zebpay Calculator — Profit/Loss Management (wos.com.zebpay)

Zebpay Bitcoin and Cryptocurrency Exchange (zebpay.Application)

Monero Wallet (xmr . org . freewallet . app)

Bitcoin Wallet by Freewallet (btc . org . freewallet . app)

BitPay — Secure Bitcoin Wallet (com.bitpay.wallet)

BTC . com — Bitcoin Walllet (com.blocktrail.mywallet)

Electroneum (com . electroneum . mobile)

Bitcoin Wallet Totalcoin — Buy and Sell bitcoin (io.totalcoin.wallet)

In addition to the extensive list of blockchain-related applications that this virus targets, the list of financial applications impacted by this virus is substantial as well.
More Information About the Anubis Virus

As mentioned above, this virus specifically targets Android users.

Its primary means of infiltration has been the Google Play store. The malware operators were able to trick users into downloading it via phishing other legitimate Google Play apps before Google detected it.

This virus has been re-engineered twice this year, and each time it has become more potent.

Specifically, this virus has the following capabilities:

Overlaying: Static (hardcoded in bot)
Overlaying: Dynamic (C2 based)
Keylogging
Contact list collection
Screen streaming
Sound recording
SMS harvesting: SMS forwarding
SMS blocking
SMS sending
Files/pictures collection
Calls: USSD request making
Ransomware: Cryptolocker
Remote actions: Data-wiping
Remote actions: Back-connect proxy
Notifications: Push notifications
C2 Resilience: Twitter/Telegram/Pastebin C2 update channels

Above, the malware's capabilites are outlined, with some of the methods of compromise hyperlinked to sources that explain the hyperlinked term for those that are not familiar with some of the means of compromise listed above.